Uh yes, that is how audit trails work
Uh yes, that is how audit trails work
An audit trail would tell you who was social-engineered, but it wouldn't have prevented the attack in the same way Wikipedia's revision history doesn't keep you from vandalizing it.
If they have logs then they can use it in the future (and it seems they do) to design better protections but only active alarms and security controls can prevent something happening in real-time.
However that does raise the question of why Twitter ever needs such access to someone's account in the first place, especially without a combination of approvals to get that access.
Auditing, post mortems, whatever diagnose the situation afterwards.
At the end of the day Uber can't stop a driver from kidnapping people, but it can provide documentation and gps coordinates to police.
My point is companies need reasonable records and audit policies and when _really bad stuff happens_ you call in the big guns for the arm of the law.
At some point you also need to trust staff and weigh that against mistakes and malicious intent.
In short, security remains an imperfect balance of practicality
>But while logging helps with investigations, only alarms or constant reviews can turn logs into something that can prevent breaches.